Impersonation Vulnerability in FreshRSS Self-Hosted Feed Aggregator
CVE-2025-46341
What is CVE-2025-46341?
FreshRSS, a self-hosted RSS feed aggregator, is susceptible to a user impersonation vulnerability when utilizing HTTP authentication through a reverse proxy. Attackers can deceive the system into believing they are another user by manipulating the Remote-User or X-WebAuth-User headers during crafted requests. To exploit this issue, they need prior knowledge of the FreshRSS instance’s IP address, the admin's username, and must possess an account on the system. This vulnerability facilitates unauthorized access to internal services and may enable privilege escalation under certain configurations. FreshRSS version 1.26.2 addresses this flaw, highlighting the importance of prompt updates to safeguard user accounts.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FreshRSS < 1.26.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
